Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS) logo

GIAC iOS and macOS Examiner

Domain 2Objective 2

Log Analysis and Timeline Creation GIME Practice Questions (Page 3)

Part of the Forensic Analysis and Artifacts domain, which makes up ~23% of our current practice bank. GIAC (SANS) does not publish an official question count, but from its 120-minute exam (~50–80 total, ~12–18 in this domain), expect 4–6 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)

28questions here
6free pages
5concepts

Questions 11–15

  1. 11application · medium

    You are building a timeline from iOS logs. You have entries from the unified log and crash reports. You notice that the crash report timestamps are in Unix epoch format, while the unified log uses ISO 8601. What is the best approach?

    Select an answer first
  2. 12application · medium

    An examiner is investigating an iOS device for potential unauthorized access. The examiner has access to the device's unified log, a plist file from a third-party app, and a SQLite database from the same app. The unified log shows an app launching at 10:15:00, the plist shows a configuration change at 10:15:30, and the SQLite database shows a data export at 10:16:00. The examiner needs to determine if the configuration change triggered the data export. Which log source would be most relevant to establish causation?

    Select an answer first
  3. 13application · medium

    An examiner has built a timeline from macOS logs and a third-party application's SQLite database. The timeline shows a user logged in at 09:00, opened a document at 09:05, and sent an email at 09:10. However, the examiner finds a unified log entry showing a process crash at 09:03 that is not in the timeline. What should the examiner do to validate the timeline?

    Select an answer first
  4. 14application · medium

    An examiner is analyzing a macOS system and needs to locate logs related to a specific application's network activity. The examiner knows the application stores data in a SQLite database and uses a plist for configuration. Which log source would provide the most direct evidence of network connections made by the application?

    Select an answer first
  5. 15expert · hard

    An examiner is validating a timeline built from macOS unified logs and a third-party application's SQLite database. The timeline shows a user logged in at 09:00, opened a file at 09:05, and sent an email at 09:10. However, the examiner finds a unified log entry showing a process crash at 09:03 and a database record showing a file modification at 09:04. The crash is not in the timeline, and the file modification is not in the timeline. What is the most appropriate action to validate the timeline?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by GIAC (SANS). “GIME” is a trademark of its owner, used for identification only.